Discussion in 'Off Topic [BG]' started by Thor, Dec 5, 2003.

    Well, it started last night. Some yahoo in our office tried to access a porn site, and it grabbed his browser, added a menu bar to IE, changed the home page settings or redirected it to that site, and added 4 Internet URL shortcuts to each Windows NT users desktop,

    Paris Hilton Video
    Portal Searching

    By this morning the server ground to a halt. The boss was in Pittsburgh between planes and it fell to me , Mr Fish sales guy, to reboot - cold boot the server and fix each work station.

    Basically, I deleted the shortcuts, emptied the recycle bins, changed the homepages back, deleted all cookies and temporary internet files, and went to the IE properties advanced settings and disabled install on demand settings and disabled allow 3rd party browser extensions, applied that.

    Then I searched the whole network for any other URL's like the above and came up clean.

    Anybody run into this? It seems like a very aggressive Java applet or something?

    A lot of you are IT guys, so I was wondering if anyone has heard of a source file that needs to be removed as well. 3 or 4 people I have talked have complained about similar horror shows in the recent past.

    It has been an interesting day.

    Any suggestions, pass'em on (Windows 2000 server,
    NT system )


    Thanks Peter!

    I'll pass that suggestion on to the boss.

    Something tells me that quite a few internet connections in this building are gonna be cancelled on Monday.

    I hope mine isn't one of them.

    If I disappear for a while, you'll know why.
    Dang idiots ...
  3. embellisher

    embellisher Holy Ghost filled Bass Player Supporting Member

    Didn't you misspell the last word in the thread title?
  4. I've gotten a fair share of this crap, and everyone says adaware, but it doesn't seem to find the real problem.

    Press ctrl+alt+delete, and go to processes. Find any unidentified processes run by "user", and write their names down. End them. Find them on your hd using search, and delete them. Their usually a .exe located somewhere in the window directory.

    Make sure you're not deleting things you don't want to delete though-just make sure all known processes are accounted for.
  6. I had that one coming, but it's mostly AIM related crap.... eh, on second thought, i'm not sure which is worse...
  7. bentem


    Oct 18, 2002
    Rockville, MD
    i had a virus on my computer recently that sounds kind of like that, i got it from AIM, but i also got the homepage redirected, paris hilton popups, plus a bunch of other popups. I got rid of it with adaware. I think it was called trojan, or adclicker.something.
  8. While we're on the subject, is that really Paris Hilton in the video?
  9. Benjamin Strange

    Benjamin Strange Commercial User

    Dec 25, 2002
    New Orleans, LA
    Owner / Tech: Strange Guitarworks
    Two words: Apple Safari.

    No pop ups whatsoever. Wonderful.

    Did you find out which guy downloaded the porn? I can understand surfing for porn on your own time, but not at work. This guy should lose his job after all the mess it's caused.
  11. Yes, yes it is
  12. Excellent.

  13. Matt Till

    Matt Till

    Jun 1, 2002
    Edinboro, PA
    As a person who has never seen this video, I have to ask.

    Who the hell is Paris Hilton. I mean I see her everywhere because now she has a show + sex tape which amazingly came out at the same time... hmmm that doesn't sound like an accident. So I know what she looks like, hella unatractive IMO. I don't dig the "I do massive amounts of cocaine/sorority girl look." But anyway, is the only reason she was famous before that is she's a rich bitch? I mean, Hilton hotels etc. But... yeah. Famous for being rich or what?
  14. She's an example of the distortive effect of having virtually all of our media outlets based in New York. Basically, she goes to a lot of parties and gets really drunk, spends lots of money on clothes and drugs, and is a slut. This wouldn't be anything special but for the fact that there are certain portions of the New York media that are, for lack of a more polite term, starf***ers. This goes with the territory of huge, self-important, insular cities.

    The Hilton girls are anomalous because, unlike most children of old money, they keep a high profile. The concept of noblesse oblige still has some currency, but Paris and Nicky just sorta fly in its face.
  15. Lackey


    May 10, 2002
    Los Angeles
    Neither of them is attractive either, Paris is the least attractive.

    Money makes you beautiful ey? Yeah right....

    Hehe, it'd be great for her to get a bloody nose on a red carpet strip or something, just to stir up more controversy.
  16. Ty McNeely

    Ty McNeely

    Mar 27, 2000
    Check out Spybot too. There is another good program that actually BLOCKS the ads from being able to download themselves onto your comp (could be SpyBot), but I can't remember what it is. Give this thread awhile and somebody will pop up with the name of whatever it is I'm thinking of.

    I'm not at MY computer now and won't be for about 5 days or I would tell you myself:)
  17. The commercial version of Ad-aware blocks the installation of adware/spyware in real time, but I'm not prepared to drop $40 for it. On the other hand, it'd be a great institutional/corporate license purchase.
  18. MJ5150

    MJ5150 Terrific Twister

    Apr 12, 2001
    Olympia, WA
    If you decide to follow the advice of DaveyO, but are not sure what is safe to keep and what is safe to end, check out this website.....Task List Programs

    It lists all of those confusing exe files, and what they do. It even tells you if they are safe to end.

  19. nonsqtr

    nonsqtr The emperor has no clothes!

    Aug 29, 2003
    Burbank CA USA
    Isn't there an IE security setting that prevents peoples' applets from changing your properties?

